Linux Kernel do_brk Function Boundary Condition Vulnerability

BID:9138

Info

Linux Kernel do_brk Function Boundary Condition Vulnerability

Bugtraq ID: 9138
Class: Boundary Condition Error
CVE: CVE-2003-0961
Remote: No
Local: Yes
Published: Dec 01 2003 12:00AM
Updated: Jul 12 2009 12:56AM
Credit: Discovery of this vulnerability has been credited to Andrew Morton. This issue was also independently discovered by Paul Starzetz <[email protected]>.
Vulnerable: VMWare ESX Server 2.0.1 build 6403
VMWare ESX Server 2.0.1
VMWare ESX Server 2.0
VMWare ESX Server 1.5.2
Trustix Secure Linux 2.0
Sun Cobalt RaQ 550
SmoothWall Express 2.0
Linux kernel 2.6 -test9
Linux kernel 2.6 -test5
Linux kernel 2.6 -test4
Linux kernel 2.6 -test3
Linux kernel 2.6 -test2
Linux kernel 2.6 -test1
Linux kernel 2.5.69
Linux kernel 2.5.68
Linux kernel 2.5.67
Linux kernel 2.5.66
Linux kernel 2.5.65
Linux kernel 2.5.64
Linux kernel 2.5.63
Linux kernel 2.5.62
Linux kernel 2.5.61
Linux kernel 2.5.60
Linux kernel 2.5.59
Linux kernel 2.5.58
Linux kernel 2.5.57
Linux kernel 2.5.56
Linux kernel 2.5.55
Linux kernel 2.5.54
Linux kernel 2.5.53
Linux kernel 2.5.52
Linux kernel 2.5.51
Linux kernel 2.5.50
Linux kernel 2.5.49
Linux kernel 2.5.48
Linux kernel 2.5.47
Linux kernel 2.5.46
Linux kernel 2.5.45
Linux kernel 2.5.44
Linux kernel 2.5.43
Linux kernel 2.5.42
Linux kernel 2.5.41
Linux kernel 2.5.40
Linux kernel 2.5.39
Linux kernel 2.5.38
Linux kernel 2.5.37
Linux kernel 2.5.36
Linux kernel 2.5.35
Linux kernel 2.5.34
Linux kernel 2.5.33
Linux kernel 2.5.32
Linux kernel 2.5.31
Linux kernel 2.5.30
Linux kernel 2.5.29
Linux kernel 2.5.28
Linux kernel 2.5.27
Linux kernel 2.5.26
Linux kernel 2.5.25
Linux kernel 2.5.24
Linux kernel 2.5.23
Linux kernel 2.5.22
Linux kernel 2.5.21
Linux kernel 2.5.20
Linux kernel 2.5.19
Linux kernel 2.5.18
Linux kernel 2.5.17
Linux kernel 2.5.16
Linux kernel 2.5.15
Linux kernel 2.5.14
Linux kernel 2.5.13
Linux kernel 2.5.12
Linux kernel 2.5.11
Linux kernel 2.5.10
Linux kernel 2.5.9
Linux kernel 2.5.8
Linux kernel 2.5.7
Linux kernel 2.5.6
Linux kernel 2.5.5
Linux kernel 2.5.4
Linux kernel 2.5.3
Linux kernel 2.5.2
Linux kernel 2.5.1
Linux kernel 2.5 .0
Linux kernel 2.4.22
+ Devil-Linux Devil-Linux 1.0.5
+ Devil-Linux Devil-Linux 1.0.4
+ Mandriva Linux Mandrake 9.2 amd64
+ Mandriva Linux Mandrake 9.2
+ Redhat Fedora Core1
+ Slackware Linux 9.1
Linux kernel 2.4.21
+ Mandriva Linux Mandrake 9.1 ppc
+ Mandriva Linux Mandrake 9.1
+ Redhat Desktop 3.0
+ Redhat Enterprise Linux AS 3
+ Redhat Enterprise Linux ES 3
+ Redhat Enterprise Linux WS 3
+ S.u.S.E. Linux Personal 9.0 x86_64
+ S.u.S.E. Linux Personal 9.0
+ SuSE SUSE Linux Enterprise Server 8
Linux kernel 2.4.20
Linux kernel 2.4.19
+ Conectiva Linux Enterprise Edition 1.0
+ MandrakeSoft Corporate Server 2.1 x86_64
+ MandrakeSoft Corporate Server 2.1
+ MandrakeSoft Multi Network Firewall 2.0
+ Mandriva Linux Mandrake 9.0
+ Slackware Linux -current
+ SuSE Linux 8.1
+ SuSE SUSE Linux Enterprise Server 8
+ SuSE SUSE Linux Enterprise Server 7
Linux kernel 2.4.18
+ Astaro Security Linux 2.0 23
+ Astaro Security Linux 2.0 16
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.1
+ Mandriva Linux Mandrake 8.0
+ Redhat Advanced Workstation for the Itanium Processor 2.1 IA64
+ Redhat Advanced Workstation for the Itanium Processor 2.1
+ Redhat Enterprise Linux AS 2.1 IA64
+ Redhat Linux 8.0
+ Redhat Linux 7.3
+ S.u.S.E. Linux Connectivity Server
+ S.u.S.E. Linux Database Server 0
+ S.u.S.E. Linux Firewall on CD
+ S.u.S.E. Linux Office Server
+ S.u.S.E. Linux Personal 8.2
+ S.u.S.E. SuSE eMail Server 3.1
+ S.u.S.E. SuSE eMail Server III
+ SuSE Linux 8.1
+ SuSE Linux 8.0
+ SuSE Linux 7.3
+ SuSE Linux 7.2
+ SuSE Linux 7.1
+ SuSE Linux Openexchange Server
+ SuSE SUSE Linux Enterprise Server 8
+ SuSE SUSE Linux Enterprise Server 7
+ Turbolinux Turbolinux Server 8.0
+ Turbolinux Turbolinux Server 7.0
+ Turbolinux Turbolinux Workstation 8.0
+ Turbolinux Turbolinux Workstation 7.0
Linux kernel 2.4.17
Linux kernel 2.4.16
Linux kernel 2.4.15
Linux kernel 2.4.14
Linux kernel 2.4.13
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Workstation 3.1.1
Linux kernel 2.4.12
Linux kernel 2.4.11
Linux kernel 2.4.10
Linux kernel 2.4.9
+ Redhat Enterprise Linux AS 2.1 IA64
+ Redhat Enterprise Linux AS 2.1
+ Redhat Enterprise Linux ES 2.1 IA64
+ Redhat Enterprise Linux ES 2.1
+ Redhat Enterprise Linux WS 2.1 IA64
+ Redhat Enterprise Linux WS 2.1
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.2 alpha
+ Redhat Linux 7.1 ia64
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1 alpha
+ Sun Linux 5.0.5
+ Sun Linux 5.0.3
+ Sun Linux 5.0
Linux kernel 2.4.8
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.1
+ Mandriva Linux Mandrake 8.0
Linux kernel 2.4.7
+ Redhat Linux 7.2
+ SuSE Linux 7.2
+ SuSE Linux 7.1
Linux kernel 2.4.6
Linux kernel 2.4.5
+ Slackware Linux 8.0
Linux kernel 2.4.4
+ SuSE Linux 7.2
Linux kernel 2.4.3
+ Mandriva Linux Mandrake 8.0 ppc
+ Mandriva Linux Mandrake 8.0
Linux kernel 2.4.2
Linux kernel 2.4.1
Linux kernel 2.4
Astaro Security Linux 4.0 16
Astaro Security Linux 4.0 08
Not Vulnerable: SGI ProPack 2.3
Linux kernel 2.6 -test9
Linux kernel 2.6 -test8
Linux kernel 2.6 -test7
Linux kernel 2.6 -test6
Linux kernel 2.6 -test11
Linux kernel 2.6 -test10
Linux kernel 2.4.23
+ Trustix Secure Linux 2.0
Astaro Security Linux 4.0 17

Discussion

Linux Kernel do_brk Function Boundary Condition Vulnerability

A vulnerability has been discovered in the Linux kernel when handling user-supplied data passed to the do_brk() function. The problem is said to occur due to the do_brk() function failing to carry out sufficient sanity checking when handling address data supplied by a user. As a result, an attacker may be capable of gaining access to sensitive kernel memory. This could ultimately allow for the attacker to read and write to kernel memory, effectively allowing for elevation of local privileges.

Exploit / POC

Linux Kernel do_brk Function Boundary Condition Vulnerability

A reliable exploit to provide for privilege escalation has been developed by Paul Starzetz &lt;[email protected]&gt; and Wojciech Purczynski &lt;[email protected]&gt;. This exploit is presented in the following document:
http://isec.pl/papers/linux_kernel_do_brk.pdf

Debian has stated that a program designed to exploit this issue was discovered and analyzed on a compromised system. This exploit is not publicly available, however can be assumed that this program is being used to actively exploit systems in the wild.

A proof of concept exploit designed to crash a system has been made available by Christophe Devine &lt;[email protected]&gt;. A second proof of concept making use of the sys_brk kernel call has been developed and supplied by Julien TINNES &lt;[email protected]&gt;.

CORE has developed a working commercial exploit for their IMPACT
product. This exploit is not otherwise publicly available or known
to be circulating in the wild.

Solution / Fix

Linux Kernel do_brk Function Boundary Condition Vulnerability

Solution:
Sun has released a fix to address this issue in the Sun Cobalt RaQ 550. The fix is linked below.

Debian has released an advisory (DSA 423-1) that addresses the issue that is described in this BID for the IA-64 architecture. Further details regarding obtaining and applying fixes can be found in the referenced advisory.

RedHat has released security advisories RHSA-2003-389 and RHSA-2003:392-00 to address this issue. Additional information about associated fixes can be found in the appropriate advisory reference.

RedHat has also released advisory RHSA-2003:368-11 for affected versions of Enterprise Linux and Advanced Workstation Linux. Affected users are advised to run up2date to resolve this issue.

Debian has released a security advisory DSA-403-1 which contains a number of fixes to address this issue. Users are advised to see the referenced advisory for further details on how to obtain and apply fixes.

Mandrake has released a security advisory (MDKSA-2003:110) including fixes to address this issue. Information on how to obtain and apply fixes can be found in the referenced advisory.

Trustix has released a security advisory (TSLSA-2003-0046) including fixes to address this issue. Fixes are available below.

This issue has also been addressed in the Linux 2.4.23 and 2.6.0-test6 releases. Users are advised to upgrade as soon as possible.

Astaro has released fixes Astaro Security Linux 4.017 (new V4 ISO) and Up2date 4.017 to address this issue. Please see the referenced web sites for more information.

Slackware Linux has released an advisory SSA:2003-336-01 including fixes to address this issue.

SGI has released an advisory (20031201-01-A) to address this issue. SGI have reported that SGI ProPack version 2.3 is not vulnerable to this issue, customers who have not received ProPack version 2.3 CD's are advised to contact the SGI Support Provider. Please see the referenced advisory for further details.

TurboLinux has released a security announcment including fixes to address this issue.

Yellow Dog Linux has released advisory YDU-20031203-1 to address this issue.

Advisory SuSE-SA:2003:049 has been released by SuSE to resolve this issue.

Gentoo has released advisory 200312-02 to address this issue. Affected users are advised to perform the following actions:

emerge sync
emerge -pv [your preferred kernel sources]
emerge [your preferred kernel sources]
[update the /usr/src/linux symlink]
[compile and install your new kernel]
[emerge any necessary kernel module ebuilds]
[reboot]

Conectiva has released a security advisory CLA-2003:796 including fixes to address this issue.

SmoothWall has released fixes to address this issue in SmoothWall Express 2.0. Users are advised to obtain the fixes through the SmoothWall interface. Please see the referenced web page for more information. Users may download the fixes1 patch by carrying out the following steps:

Go to Maintenance -> Updates on your SmoothWall web interface, and upload the file called fixes1.

SGI has released a security advisory 20040102-01-U including fixes to address this issue. Please see the attached advisory for more information.

Debian has released advisory DSA-433-1 this issue for the mips and mipsel architectures.

VMWare has released a fix to address this issue in VMWare ESX Server 2.0.1 build 6403. Please see the referenced web page for more information.

Debian has released two advisories DSA-439-1 and DSA-440-1 to address this and other issues. Please see the referenced advisories for more information.

Debian has released DSA 442-1 to provide fixes for s390 platforms. Please see the attached advisory for further information.

Debian has released DSA 450-1 to provide MIPS kernel fixes. Please see the attached advisory for further details.

Debian has released DSA 470-1 to address this and other issues in the HP Precision architecture. Please see the referenced advisory for more information.

VMWare advisory and fixes available for their ESX server package. Please see th reference section for more information.

Debian has released advisory DSA 475-1 with fixes dealing with this and other issues for the HP Precision architecture.

Fixes:


Sun Cobalt RaQ 550

Trustix Secure Linux 2.0

VMWare ESX Server 2.0

VMWare ESX Server 2.0.1 build 6403

VMWare ESX Server 2.0.1

Linux kernel 2.4

Linux kernel 2.4.1

Linux kernel 2.4.11

Linux kernel 2.4.12

Linux kernel 2.4.13

Linux kernel 2.4.14

Linux kernel 2.4.15

Linux kernel 2.4.17

Linux kernel 2.4.18

Linux kernel 2.4.19

Linux kernel 2.4.21

Linux kernel 2.4.22

Linux kernel 2.4.3

Linux kernel 2.4.4

Linux kernel 2.4.5

Linux kernel 2.4.6

Linux kernel 2.4.7

Linux kernel 2.4.8

Linux kernel 2.4.9

Linux kernel 2.5 .0

Linux kernel 2.5.10

Linux kernel 2.5.11

Linux kernel 2.5.12

Linux kernel 2.5.15

Linux kernel 2.5.16

Linux kernel 2.5.17

Linux kernel 2.5.18

Linux kernel 2.5.19

Linux kernel 2.5.2

Linux kernel 2.5.21

Linux kernel 2.5.22

Linux kernel 2.5.23

Linux kernel 2.5.24

Linux kernel 2.5.25

Linux kernel 2.5.26

Linux kernel 2.5.27

Linux kernel 2.5.28

Linux kernel 2.5.29

Linux kernel 2.5.3

Linux kernel 2.5.30

Linux kernel 2.5.31

Linux kernel 2.5.32

Linux kernel 2.5.33

Linux kernel 2.5.35

Linux kernel 2.5.36

Linux kernel 2.5.37

Linux kernel 2.5.4

Linux kernel 2.5.40

Linux kernel 2.5.42

Linux kernel 2.5.43

Linux kernel 2.5.45

Linux kernel 2.5.48

Linux kernel 2.5.49

Linux kernel 2.5.5

Linux kernel 2.5.51

Linux kernel 2.5.52

Linux kernel 2.5.53

Linux kernel 2.5.54

Linux kernel 2.5.55

Linux kernel 2.5.56

Linux kernel 2.5.57

Linux kernel 2.5.58

Linux kernel 2.5.59

Linux kernel 2.5.6

Linux kernel 2.5.60

Linux kernel 2.5.62

Linux kernel 2.5.63

Linux kernel 2.5.64

Linux kernel 2.5.65

Linux kernel 2.5.67

Linux kernel 2.5.7

Linux kernel 2.5.8

Linux kernel 2.6 -test4

Linux kernel 2.6 -test2

Linux kernel 2.6 -test3

Linux kernel 2.6 -test1

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report